Thursday 17 Sep 2026 Abu Dhabi UAE
Prayer Timing
Today's Edition
Today's Edition
AI

AI security and governance define next phase of cyber defence – experts

AI security and governance define next phase of cyber defence – experts
17 Sep 2026 20:27

BATOOL GHAITH (DUBAI)

As the UAE becomes more digitally connected, cybersecurity is shifting from protecting individual systems to securing the wider ecosystem around them.

Cybersecurity experts, speaking to Aletihad at GISEC Global 2026, said the next phase of cyber defence will increasingly depend on securing identities and data, setting boundaries around AI systems and protecting the interconnected infrastructure on which cities such as Abu Dhabi depend.

Kaspersky Security Network figures revealed that 92% of UAE respondents store sensitive personal data electronically, including identification documents, financial details, healthcare information or photo archives, while 44% encountered an online scam or attempted scam in the past 12 months.

Kaspersky also said that its detection systems stopped 5.4 million attacks from online resources in the UAE during the first half of the year.

From Endpoint to Trust

Victor Juan Mateu, Chief Researcher at the Cryptography Research Center at Abu Dhabi’s Technology Innovation Institute (TII), said increasingly connected environments require protection across multiple layers rather than at a single point.

“When we are talking about the connected community and connected interfaces, what we need is protection from endpoints, but also from the root of trust,” Mateu told Aletihad.

He said that Abu Dhabi already has strong cybersecurity governance, with policies helping entities advance digital transformation while addressing security requirements.

As demand for AI increases computing and power requirements, Mateu said the same technology can strengthen both attackers and defenders. “AI this year has been instrumental in securing a lot of web browsers and operating systmes we use today,” he said, while noting that the technology has also helped attackers identify weaknesses.

Secure Foundation for AI

Yazan Khasawneh, Cybersecurity Director for the UAE at Microsoft, said that as AI becomes embedded more deeply into digital infrastructure, organisations will have to secure not only human users but also AI agents operating across systems.

“Our number one concern as organisations should be protecting our identity,” Khasawneh told Aletihad. He pointed to multi-factor authentication and passkeys as increasingly important because once an attacker assumes a legitimate identity, the compromise can spread across everything that user is authorised to access.

For Khasawneh, cybersecurity should enable rather than obstruct AI adoption.

“Security will not be the brakes on AI. It will be the foundation on which we build AI,” he noted.

Human Oversight Remains Key

Hadi Anwar, CEO of CPX, said the expansion of AI is turning security into a broader business issue rather than one confined to technology teams.

“Trust enables AI adoption, and security enables trust,” Anwar told Aletihad.

At an organisational level, Anwar said companies need clear accountability, identity governance, least-privilege access, data protection and integrated security operations.

Human oversight remains necessary for decisions involving critical systems, sensitive information or essential services, he said.

Intelligence Sharing Frameworks

Dmitry Volkov, CEO of Group-IB, said AI-era security begins with controlling where data is stored, how it is protected and how organisations are permitted to use AI.

He also noted that increasingly interconnected economies require organisations to move beyond defending themselves in isolation.

“Cybercriminals are often more willing to collaborate and exchange information, but organisations face restrictions around sharing sensitive and private data,” he added.

This creates a need for protocols that allow threat intelligence to be exchanged in real time while preserving privacy, Volkov noted.

Data Sharing Risks

Vignesh Kumar, Senior Product Manager for RMEA at Sangfor, said organisations should be cautious about both the information they share with AI systems and the decisions they allow those systems to make.

“Some people are blindly believing in sharing data with AI, which leads to bigger risk and more harm,” he told Aletihad.

Kumar said AI outputs should not be treated as automatically reliable, particularly where critical decisions are involved. “We need to always have a layer of approval for certain critical decisions or critical answers,” he added, noting that the same principle should apply to sensitive corporate data.

He also warned that attackers are increasingly using AI themselves, meaning conventional cybersecurity tools may not always be enough to identify emerging threats.

In this regard, Kumar emphasided that defensive systems also need AI capabilities capable of identifying and responding to attacks generated or accelerated by other AI systems.

Copyrights reserved to Aletihad News Center © 2026